Authenticated Remote Code Execution in Nginx Proxy Manager by Nginx
CVE-2026-40519
7.7HIGH
What is CVE-2026-40519?
Nginx Proxy Manager versions 2.9.14 through 2.15.1 are susceptible to an authenticated remote code execution vulnerability due to improper handling of user inputs. Specifically, the vulnerability is triggered via the dns_provider_credentials field during the execution of the setupCertbotPlugins() function. Attackers possessing 'certificates:manage' permissions can exploit this flaw by injecting malicious code that gets executed without proper validation or escaping, leading to arbitrary command execution when the backend is restarted.
Affected Version(s)
nginx-proxy-manager 2.9.14 <= 2.15.1
nginx-proxy-manager 2.9.14 <= 2.15.1
nginx-proxy-manager a5db5ed156355e3088e7d1ceb0533d4bae922def
